ITbuilder Ltd.

We provide managed IT services including: fully or co-managed IT support and security, cloud hosting and productivity solutions, data protection and recovery, telephony and managed networks.

Many business leaders today have the same concern: are we actually in control of the AI tools driving our day-to-day dec...
21/09/2026

Many business leaders today have the same concern: are we actually in control of the AI tools driving our day-to-day decisions?

Rapid AI adoption is rewriting the expectations of board-level governance. The risks—data leakage, regulatory missteps, unintended automation—now reach far beyond IT. Relying solely on certifications or security tools is no longer enough when shadow AI can surface in any team, at any time.

The lesson for SME directors is clear: true AI governance must be deliberate, policy-led, and visibly owned at the top table. Pause. Define boundaries. Make sure ownership of AI risk sits where it belongs—at the heart of business leadership.

Responsible progress always beats unchecked innovation.

Read the full article here:

As the pace of AI adoption accelerates, Microsoft's AI Code of Conduct marks a pivotal shift in setting governance standards. This article explores why effective AI governance – not just technical controls – must become a board-level priority for UK SME leaders.

21/09/2026
18/09/2026

Meet the 👋

Say hello to Sam Copsey, our new AI & Automation Lead.

Sam is heading up our internal AI and automation work - with a goal that's refreshingly simple: amplify what our people already do best, and give them back time to focus on customers, not admin.

That means working across every function of the business to find the real opportunities, prioritise them properly, and actually deliver them - with the guardrails and measurement to back it up, not just switch things on and hope.

Sam's background is engineering at scale - most recently leading an engineering and innovation function with a strong public sector focus, and before that, consulting on cloud migrations into Azure and AWS.

One lesson that's stuck: the best automation isn't the cleverest one, it's the one people actually adopt.

Outside of work, you'll usually find Sam at a gig or a festival
Welcome to the team. 🎉

Many SME boards are unaware of how rapidly unchecked AI deployments are changing the organisation’s risk profile.AI tool...
14/09/2026

Many SME boards are unaware of how rapidly unchecked AI deployments are changing the organisation’s risk profile.

AI tools foster innovation, but when they’re launched without proper permissions reviews or governance oversight, the real impact is felt at the board level. The trouble isn’t just technical—regulatory, commercial, and reputational risk pile up quickly and quietly.

In my experience, the most effective boards now treat AI governance as a core leadership function, not a subsidiary IT concern. It’s about demanding transparency on who can access what, insisting on rigorous sign-off, and connecting AI risk directly with business outcomes.

Boardroom accountability is the difference between seizing AI’s potential and sleepwalking into an avoidable crisis.

Read the full article here:

Unchecked AI deployments without proper permissions reviews expose UK SMEs to strategic, regulatory, and operational risks. This article explains why board-level oversight is essential for AI governance, practical steps for risk management, and the long-term business consequences of neglecting AI pe...

14/09/2026

Many SME boards are unaware of how rapidly unchecked AI deployments are changing the organisation’s risk profile.

AI tools foster innovation, but when they’re launched without proper permissions reviews or governance oversight, the real impact is felt at the board level. The trouble isn’t just technical—regulatory, commercial, and reputational risk pile up quickly and quietly.

In my experience, the most effective boards now treat AI governance as a core leadership function, not a subsidiary IT concern. It’s about demanding transparency on who can access what, insisting on rigorous sign-off, and connecting AI risk directly with business outcomes.

Boardroom accountability is the difference between seizing AI’s potential and sleepwalking into an avoidable crisis.

Read the full article here:

The "Who Can See What?" Problem AI Keeps ExposingEvery SharePoint environment has a bit of a past.A finance folder from ...
10/09/2026

The "Who Can See What?" Problem AI Keeps Exposing

Every SharePoint environment has a bit of a past.
A finance folder from years ago. A project site someone set up "just for now." Access granted for one deadline and never taken away.

Nobody did anything wrong. It's just what happens over time - teams change, permissions quietly pile up. For years, that was fine, mostly because nobody looked too closely.

AI changes that.

Copilot doesn't create the mess. It just finds it faster.

Tools like Copilot are very good at finding and using whatever a person already has permission to see. Which sounds harmless - until you realise most of us don't actually know the answer to a simple question:

Who can see what, right now, in our environment?

A few honest questions worth asking

🔎 Do we know who has access to our sensitive files and sites?
📁 Do we know where our most important information actually lives?
👥 Is that access there because someone needs it - or because it was granted once and never revisited?
🔄 Do we check permissions when people change roles or leave?
🚦 If we found something wrong tomorrow, could we fix it?

None of these are really AI questions. They're just good housekeeping - AI just raises the stakes on getting them right.

What this looks like in practice

Picture an organisation with thousands of SharePoint documents built up over the years. Nobody set out to create a mess - different teams, different habits, some sites managed, others forgotten.

Now add AI.

Nothing changes about who's technically allowed to see what. But information that used to take real effort to find is now one prompt away. That's the moment the risk conversation shifts.

The question worth asking before "are we ready for Copilot?"

Try this instead: are we comfortable with what our current permissions would let someone find?

That's harder to answer honestly - and more useful to ask before rollout, not after.

This isn't about SharePoint being unsafe, or locking everything down. It's about knowing where the boundaries are, so the right people have access for the right reasons.
AI readiness starts with knowing your own data.

Not sure what your permissions would reveal?
That's what a SharePoint data governance review is for. Talk to the ITBuilder AI Practice team - we'll help you find out before AI does it for you.

10/09/2026

Your Intune licence count may be correct. But can you trust the devices accessing your business - and the data and AI capabilities they can now reach?

When organisations review Microsoft Intune, the conversation often starts with licences.
Do we have enough?

But a licence gives you the capability to manage a device. It doesn't make that device secure.

For years, security was mostly about identity - who you are, can you prove it.

Today that's only half the picture.

The question is also: what device are you using, and can we trust it right now?

🛡️ Enrolled - is it registered and visible to IT?
🔐 Encrypted - if it's lost tomorrow, is the data protected?
🔄 Updated - is it patched and running supported software?
🚦 Controlled - if it stops meeting the standard, can access be restricted automatically?

None of this is exotic.

But once AI is in the mix, these fundamentals matter a lot more - AI can make whatever a device has access to much easier to find, connect and use.

A licence doesn't make a device trustworthy. The device either meets the bar - or it doesn't.

How many devices in your environment would actually pass these four checks today?

Most business leaders are keen to unlock the productivity and innovation that AI tools like Microsoft Copilot promise—bu...
07/09/2026

Most business leaders are keen to unlock the productivity and innovation that AI tools like Microsoft Copilot promise—but very few realise just how exposed their existing Microsoft 365 environment might be.

The shift to AI isn't just about activating a new feature; it's about ensuring your underlying data structures, permissions and risk management are mature enough to handle these powerful capabilities.

In my experience, without clear AI governance and a practical deployment checklist, organisations risk surfacing sensitive information to the wrong people and falling short of data protection obligations long before they see any return on investment.

Before bringing Copilot in, IT leaders should treat governance not as a one-off project, but as an ongoing discipline shaping both security and trust.

Read the full article here:

Before rolling out Microsoft Copilot, IT leaders must apply a robust AI governance checklist. Learn the essential steps to secure Microsoft 365 environments, address data protection, and enable responsible AI adoption in your SME.

What "Compliant Device" Actually Means in PracticeYour Intune licence count may be correct. But can you trust the device...
03/09/2026

What "Compliant Device" Actually Means in Practice

Your Intune licence count may be correct. But can you trust the devices accessing your business - and everything Copilot can now surface through them?

When organisations review Microsoft Intune, the conversation often starts with licences.
Do we have enough?

But licensing is only part of the picture. A licence gives you the capability to manage a device. It doesn't make that device secure.

For leadership, the more important question is:

Can we confidently say that the devices accessing our business data meet our security requirements?

That's where device enrolment and compliance matter - and it becomes a much bigger question once AI tools are part of the picture.

For years, security was largely focused on identity:

Who are you?
Can you prove it?

Today, that's only half the picture. The question is also:

What device are you using - and can we trust it right now?
What does "trusted" actually mean?

🛡️ Enrolled
🛡️ Encrypted
🛡️ Updated
🛡️ Conditional Access

That's the difference between monitoring risk and acting on it.

Why should leadership care?
Because an unmanaged or non-compliant device isn't simply an IT problem.

It can become a data protection problem, an operational problem, or a business risk. Personal devices accessing corporate information and now AI tools that can search across it create another layer of complexity.

If something goes wrong, the organisation may need to understand what data was accessed, from which device, under what controls, and whether that device was appropriately managed.

That's a very different conversation from: "We forgot to update the laptop."

Four checks. One bigger question.

Enrolled. Encrypted. Updated. Controlled.

Nothing exotic. But these four checks help answer a much bigger business question:

Do we actually have control over the devices that can access our data and everything AI can now do with it?

Because a licence doesn't make a device trustworthy. The device either meets the security bar, or it doesn't.

And that's why, when reviewing Intune ahead of AI adoption, device posture matters just as much as licence count.

Not sure which devices in your environment would pass these four checks today? That's exactly what a compliance review is designed to find out.

AI regulation is no longer a distant concern—it's becoming a direct test of governance and risk ownership for SME boards...
01/09/2026

AI regulation is no longer a distant concern—it's becoming a direct test of governance and risk ownership for SME boards.

Regulatory expectations around artificial intelligence are evolving rapidly. The pressure is mounting for directors to move beyond abstract policies and take real, accountable control over AI risk. This means understanding where AI touches your operations, clarifying who owns the exposure, and ensuring that both ethics and compliance are embedded in decision-making—not bolted on after the fact.

For many leadership teams, the real challenge isn’t technical—it's how to turn governance principles into practical action, amidst regulatory ambiguity and rising business stakes.

In a climate where readiness is the new advantage, the most resilient businesses will be those whose boards own the AI agenda, not just their IT departments.

Read the full article here:

Staying ahead of AI regulation in the UK is now a strategic imperative for SME directors. Explore what has changed in 2026, what it means for governance, and how to build readiness for AI risk and compliance challenges.

Address

2A Great Northern Works, Hartham Lane
Hertford
SG141QW

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm

Telephone

+443333440980

Alerts

Be the first to know and let us send you an email when ITbuilder Ltd. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to ITbuilder Ltd.:

Shortcuts

Share